- DCs: Windows Server 2008 R2
- Clients: Windows XP Professional / Windows 7 Enterprise
Some OU is already applied a Restricted Group policy, in which only Domain Admins and Desktop Admins are in the build-in local Administrators group. Now there are some speical users who need to have the local admin privilege for their own desktop computers.
For example,
- User1 needs to be in Computer1's local Administrators group, but User2/User3 should not be in Computer1's local Administrators group.
- User2 nneds to be in Computer2's local Administrators group, but User1/User3 should not be in Computer1's local Administrators group.
- User3 nneds to be in Computer3's local Administrators group, but User1/User2 should not be in Computer1's local Administrators group.
I don't want to create so many GPOs for every special user. Any other ways?
Thanks,
高麻雀